Vulnerabilities
21 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-5200 | The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insuffic The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-40197 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions. Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-23878 +1 in the same advisory: …23879 | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. NVD description · AI analysis pending | 9.8 group max | 2% | PoC ×2 |
| — | |
| CVE-2020-19464 | An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2020-18750 | Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file. Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2018-11686 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. NVD description · AI analysis pending | 9.8 | 53% | PoC |
| — | |
| CVE-2018-14947 +1 in the same advisory: …14946 | An issue has been found in PDF2JSON 0.69. An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete). NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — |